Cookie Policy
Last updated:
14 September 2026
At Hellomatik, we respect the information we may collect about you on this website.
Controller: HELLOMATIK, S.L. (CIF B22803126)
Contact: administracion@hellomatik.com
Effective date: 1 October 2025. Last updated: 14 September 2026.
1) Cookies and similar technologies
This policy explains how cookies and similar technologies (e.g., local storage and SDKs) may be used to operate this website, remember your preferences, secure our services and measure usage. In Spain, the use of these technologies is governed by Article 22.2 of the LSSI and, in the EU, by Article 5(3) of the ePrivacy Directive; where consent is required, it must meet GDPR standards and follow the AEPD Cookie Guide.
2) Types of cookies we may use
By purpose
Strictly necessary (technical and security): required for core functions (login, security, load balancing, fraud and bot mitigation). Consent is not required.
Preferences: remember settings such as language or interface; consent is required unless you choose the setting yourself (e.g., pick a language).
Analytics and measurement: help us understand visits and engagement; consent is required (in the UK, "Accept" and "Reject" must be equally prominent on the first screen of the banner).
Advertising and targeting (if used): interest‑based ads and remarketing; consent is required.
By duration: session cookies (deleted when you close the browser) or persistent cookies (e.g., 24 hours, 30 days or 400 days; subject to browser limits).
By party: first‑party cookies (set by hellomatik.com) or third‑party cookies (set by external providers).
3) Legal basis and consent
We do not set non‑essential cookies or technologies without prior consent. The non‑essential cookies on this website are Google's measurement cookies, for two purposes that you accept separately: analytics (Google Analytics 4) and advertising (Google Ads conversion measurement).
They are set only if you accept them in the notice shown at the foot of the first page you visit, or on this page. The notice shows "Accept" and "Decline" with equal prominence and a link to set each purpose, does not cover the page, and not answering is not consent: if you do not choose, nothing loads. The booking calendar's cookies, which are set only when you open it because they are needed for the booking you request, are described in sections 5 and 8.
4) Managing cookies
You can change your choice at any time on this page (at the end): decline all, accept all or choose each purpose. If you withdraw consent you had given, the website deletes Google's cookies for that purpose and reloads the page, so that no measurement script stays loaded. You can also delete the "hm‑consentimiento" cookie in your browser. To be able to demonstrate consent, the website records each choice with its date and the version of this policy, without your IP address or any other data that identifies you.
Browser controls: you can also block or delete cookies in your browser (Chrome, Firefox, Safari, Edge, Opera). Blocking strictly necessary cookies may stop parts of this website from working.
5) Third‑party providers and international transfers
If you accept a measurement purpose, Google Tag Manager loads and, through it, the Google Ireland Limited services you accepted: Google Analytics 4 for analytics and Google Ads for advertising. Google may transfer data to the United States under the EU‑US Data Privacy Framework and standard contractual clauses.
The booking calendar is provided by Calendly LLC, based in the United States and certified under the EU‑US Data Privacy Framework. It loads only when you press "Choose a day and time" or pick a day and time after sending the form. When it loads, Calendly and the providers it uses to secure and deliver the booking (Cloudflare, Stripe, Google reCAPTCHA and OneTrust) receive your IP address and technical browser data, and may set the cookies described in section 8.
This website hides Calendly's own cookie notice; Calendly keeps its analytics and advertising cookies switched off. Calendly's use of the data is governed by its own policy.
6) Children
Where consent is required, UK law sets the age of digital consent at 13; below that age, a holder of parental responsibility must give consent (subject to any stricter sector‑specific laws).
7) Cookie walls
We do not condition access to this website on accepting non‑essential cookies. Any future alternative model (e.g., a paid option) will follow EU guidance on freely given consent.
8) Cookies and technologies in use at present
Cookie "hm‑consentimiento" (first‑party, 6 months): stores your measurement choice (all, none or a single purpose). Exempt from consent: it is the one that remembers your choice.
Local storage "hm‑tema" and cookie "hm‑idioma" (first‑party, 1 year): remember the light or dark interface and the language. They are stored only when you choose a theme or press EN/ES; they are exempt preferences. Inferring the language from your browser sets no cookie.
Only if you accept analytics: Google Analytics 4 cookies ("_ga", "_ga_*", up to 2 years; they count visits and pages). Only if you accept advertising: Google Ads cookies ("_gcl_au", "_gcl_aw", "_gcl_gs", up to 90 days; they attribute the form you send to an ad); when you send the contact form, your email address is passed to Google hashed ("enhanced conversions") so that the enquiry is counted once; and the session storage item "hm‑origen" (first‑party, until the tab is closed) keeps the campaign parameters you arrived with (gclid, UTM) to attribute the enquiry. Signing in at app.hellomatik.com sets that platform's own strictly necessary session cookies on its domain, governed by its terms.
Only when you open the booking calendar (third‑party, needed for the booking you request): "__cf_bm" (Cloudflare, on calendly.com, 30 minutes; tells people from bots), "_cfuvid" (Cloudflare, on calendly.com, session; load balancing), "m" (Stripe, on m.stripe.com, up to 400 days; fraud prevention) and "OptanonConsent" (OneTrust, on calendly.com, up to 1 year; records that Calendly's analytics and advertising cookies are switched off). Calendly also loads Google reCAPTCHA to detect abuse, which sends technical browser data to Google.
Technical session storage when you switch language (first‑party, deleted once read): keeps your place on the page so you are not sent back to the top. Exempt from consent.
We will update this section before adding any new technology.
9) Google Consent Mode (v2)
We use Google Consent Mode v2 in its basic variant: the four permissions (ad storage, ad user data, ad personalization and analytics storage) are denied by default. Analytics storage is granted only if you accept analytics, and the three advertising permissions only if you accept advertising. Google Tag Manager and Google's other measurement scripts do not load until you accept at least one purpose. If you decline measurement, this website sends no measurement data to Google; the booking calendar, if you open it, uses Google reCAPTCHA as described in section 5.
10) Changes to this policy
We will update this page and seek new consent when introducing new purposes or vendors that require it.